add-shape-types-to-torch-model
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill instructs the agent to run local verification commands, including
pyrefly checkand a bundled shell scriptverify_port.sh. These commands are used to perform static analysis and ensure the correctness of the added type annotations, which is the primary purpose of the skill. - Indirect Prompt Injection Surface: The skill processes user-supplied PyTorch model code, creating a potential surface for indirect prompt injection. However, the risk is minimized by the skill's prescriptive "gate" system and the use of static analysis checkpoints (
reveal_type,assert_type), which focus the agent on technical code structures rather than natural language instructions within the source code. - Internal Tooling and Environment: The skill references specific internal paths and build conventions consistent with the vendor's development environment. These references are used to locate stubs and runtime extensions necessary for the shape-tracking functionality.
Audit Metadata